注意
Azure Automation State Configuration將於2027年9月30日退役,請於該日期前轉換為Azure機器配置。 欲了解更多資訊,請參閱blog文章公告。 Azure機器組態服務結合了 DSC 擴充功能、Azure Automation State Configuration 以及客戶反饋中最常被要求的功能。 Azure機器配置也包含透過支援 Arc 的伺服器 支援混合機器。
重要
2025 年 3 月 31 日,入口網站將會移除 [新增]、[撰寫組態] 和 [資源庫] 導覽連結。
警告
Azure Automation DSC for Linux 已於 2023 年 9 月 30 日正式退休。 如需詳細資訊,請參閱公告。
Azure Automation State Configuration 讓你能為伺服器指定設定,並確保這些伺服器隨時間保持在指定狀態。
- 將虛擬機器加入 Azure Automation DSC 進行管理
- 將配置上傳至 Azure Automation
- 將設定編譯成節點設定
- 將節點設定指派給受控節點
- 檢查受控節點的合規性狀態
針對此教學課程,我們會使用簡單的 DSC 設定,以確保在 VM 上安裝 IIS。
必要條件
注意
Windows Server 2008 與 Windows Server 2008 R2 已達到支援終止(EOS)。 欲了解更多資訊,請參閱Windows Server 2008 和 Windows Server 2008 R2 支援終止及執行原地升級至 Windows Server 2016、2019、2022 或 2025。 檢視你的使用情況,並相應規劃作業系統升級與遷移。
- 一個 Azure Automation 帳戶。 若要深入了解自動化帳戶及其需求,請參閱自動化帳戶驗證概觀。
- 一個運行 Windows Server 2008 R2 或更新版本的 Azure Resource Manager 虛擬機(非經典版)。 關於建立虛擬機的說明,請參見 在 Azure portal 建立你的第一個Windows虛擬機。
- Azure PowerShell module version 3.6 或更新。 執行
Get-Module -ListAvailable Az以尋找版本。 如果你需要升級,請參考安裝Azure PowerShell模組。 - 熟悉 Desired State Configuration(DSC)。 有關 DSC 的資訊,請參見 Windows PowerShell Desired State Configuration Overview。
對部分設定的支援
Azure Automation State Configuration 支援使用 部分配置。 在此情境下,DSC 會被設定為獨立管理多個設定,每個設定都從 Azure Automation 取得。 不過,每個自動化帳戶只能指派一項設定檔給一個節點。 這表示如果您要針對節點使用兩個組態,則需要兩個自動化帳戶。
如需有關如何從提取服務註冊部分組態的詳細資料,請參閱部分組態的文件。
如需團隊如何合作以協同管理伺服器,並將設定當作程式碼使用的詳細資訊,請參閱了解 DSC 在 CI/CD 管線中的角色。
登入 Azure
請使用 Connect-AzAccount 指令登入您的Azure訂閱,並依照螢幕指示操作。
Connect-AzAccount
建立並上傳配置到 Azure Automation
在文字編輯器中輸入下列項目,並將其於本機儲存為 TestConfig.ps1。
configuration TestConfig {
Node WebServer {
WindowsFeature IIS {
Ensure = 'Present'
Name = 'Web-Server'
IncludeAllSubFeature = $true
}
}
}
注意
Azure Automation 中的設定名稱必須限制在不超過 100 個字元。
在需要匯入多個模組以提供 DSC 資源的更進階案例中,請確定每個模組在設定中都有唯一的 Import-DscResource 行。
呼叫 Import-AzAutomationDscConfiguration Cmdlet,以將設定上傳至自動化帳戶中。
$importAzAutomationDscConfigurationSplat = @{
SourcePath = 'C:\DscConfigs\TestConfig.ps1'
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
Published = $true
}
Import-AzAutomationDscConfiguration @importAzAutomationDscConfigurationSplat
將設定編譯成節點設定
DSC 設定必須編譯成節點設定,才可以指派至節點。 請參閱 DSC 設定。
呼叫 Start-AzAutomationDscCompilationJob Cmdlet,以將 TestConfig 設定編譯成自動化帳戶中名為 TestConfig.WebServer 的節點設定。
$startAzAutomationDscCompilationJobSplat = @{
ConfigurationName = 'TestConfig'
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
}
Start-AzAutomationDscCompilationJob @startAzAutomationDscCompilationJobSplat
註冊一個由 State Configuration 管理的虛擬機
你可以用 Azure Automation State Configuration 管理Azure虛擬機(包括經典版和 Resource Manager)、本地虛擬機、Linux 機器、AWS 虛擬機以及本地實體機器。 本文將介紹如何僅註冊 Azure Resource Manager 虛擬機。 關於註冊其他類型機器的資訊,請參閱透過 Azure Automation State Configuration 進行管理之機器的加入程序。
呼叫 Register-AzAutomationDscNode cmdlet,將你的虛擬機Azure Automation State Configuration註冊為管理節點。
$registerAzAutomationDscNodeSplat = @{
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
AzureVMName = 'DscVm'
}
Register-AzAutomationDscNode @registerAzAutomationDscNodeSplat
指定設定模式設定
使用 Register-AzAutomationDscNode Cmdlet,以將 VM 註冊為受控節點,並指定設定屬性。 例如,您可藉由指定 ApplyOnly 作為 ConfigurationMode 屬性的值,以指定讓電腦的狀態只套用一次。 State Configuration 在初次檢查後不會嘗試套用該組態。
$registerAzAutomationDscNodeSplat = @{
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
AzureVMName = 'DscVm'
ConfigurationMode = 'ApplyOnly'
}
Register-AzAutomationDscNode @registerAzAutomationDscNodeSplat```
You can also specify how often DSC checks the configuration state by using the
`ConfigurationModeFrequencyMins` property. For more information about DSC configuration settings,
see [Configuring the Local Configuration Manager][05].
```powershell
# Run a DSC check every 60 minutes
$registerAzAutomationDscNodeSplat = @{
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
AzureVMName = 'DscVm'
ConfigurationModeFrequencyMins = 60
}
Register-AzAutomationDscNode @registerAzAutomationDscNodeSplat```
## Assign a node configuration to a managed node
Now we can assign the compiled node configuration to the VM we want to configure.
```powershell
# Get the ID of the DSC node
$getAzAutomationDscNodeSplat = @{
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
Name = 'DscVm'
}
$node = Get-AzAutomationDscNode @getAzAutomationDscNodeSplat
# Assign the node configuration to the DSC node
$setAzAutomationDscNodeSplat = @{
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
NodeConfigurationName = 'TestConfig.WebServer'
NodeId = $node.Id
}
Set-AzAutomationDscNode @setAzAutomationDscNodeSplat
此動作會將名為 TestConfig.WebServer 的節點設定,指派至已註冊的 DSC 節點 DscVm。
根據預設,DSC 節點會每隔 30 分鐘檢查節點設定的合規性。 關於如何更改合規檢查間隔的資訊,請參見 Configuring the Local Configuration Manager。
檢查受控節點的合規性狀態
您可使用 Get-AzAutomationDscNodeReport Cmdlet,以取得受控節點合規性狀態的報告。
# Get the ID of the DSC node
$getAzAutomationDscNodeSplat = @{
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
Name = 'DscVm'
}
$node = Get-AzAutomationDscNode @getAzAutomationDscNodeSplat
# Get an array of status reports for the DSC node
$getAzAutomationDscNodeReportSplat = @{
ResourceGroupName = 'MyResourceGroup'
AutomationAccountName = 'myAutomationAccount'
NodeId = $node.Id
}
$reports = Get-AzAutomationDscNodeReport @getAzAutomationDscNodeReportSplat
# Display the most recent report
$reports[0]
下一步
- 要開始,請參考 Get started with Azure Automation State Configuration。
- 欲了解如何啟用節點,請參閱 Enable Azure Automation State Configuration。
- 想了解如何編譯 DSC 配置以便指派到目標節點,請參考 Compile DSC configurations in Azure Automation State Configuration。
- 若想了解如何在持續部署流程中使用 Azure Automation State Configuration,請參見 Setup continuous deployment with Chocolatey。
- 價格資訊請參見 Azure Automation State Configuration pricing。
- 如需 PowerShell Cmdlet 參考,請參閱 Az.Automation。
- 關於使用 Azure Automation State Configuration 將機器配置到理想狀態相關的故障排除問題,請參見 Troubleshoot Azure Automation State Configuration issues。